CVE-2019-10473: Medium severity jenkins libvirt agents vulnerability
Published Oct 23, 2019
·Updated
A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:libvirt-slave<1.8.6
1.8.6
Jenkins Libvirt Slaves Jenkins<=1.8.5
Event History
Oct 23, 2019
CVE Published
via MITRE·12:45 PM
Data Sourced
via MITRE·12:45 PM
Description
May 24, 2022
Advisory Published
04:59 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-10473?
CVE-2019-10473 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-10473?
To remediate CVE-2019-10473, upgrade to the Libvirt Slaves Plugin version 1.8.6 or later.
3
Who is affected by CVE-2019-10473?
Users with Overall/Read access in Jenkins may be affected by CVE-2019-10473.
4
What does CVE-2019-10473 allow?
CVE-2019-10473 allows unauthorized users to enumerate credentials IDs stored in Jenkins.
5
Which versions of Jenkins Libvirt Slaves Plugin are vulnerable to CVE-2019-10473?
Versions of Jenkins Libvirt Slaves Plugin up to and including 1.8.5 are vulnerable to CVE-2019-10473.